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Joint letter on ‘sovereignty requirements’ in candidate European 
Cybersecurity Certification Scheme for Cloud Services 


Brussels, 16 June 2022 


The European Union Agency for Cybersecurity (ENISA) is in the process of releasing a new 
draft of the candidate European Cybersecurity Certification Scheme for Cloud Services (EUCS). 
This new draft will incorporate so-called sovereignty requirements concerning data localisation, 
headquarters and corporate control that we fear would severely damage our digital economy. 


The proposed requirements, which aim to make EU data ‘immune’ from non-EU laws, 

fundamentally misunderstand the reality of European businesses operating internationally. As 
we explain at length in a separate report,' these requirements will restrict choice and quality in 
the European cloud market without solving the issue of non-EU access they purport to tackle. 


Instead, they would have the very illogical consequence of making it more difficult for European 
companies to operate globally, including with our crucial US ally, hampering their growth and 
competitiveness. The rules will also have a negative impact on cybersecurity, as under this 
scheme no provider will be able to offer high-level EU-certified data transfers to third countries. 
This is contrary to the objectives of a cybersecurity certification scheme.? 


This is a political discussion, not a technical one. lts major economic implications should be 
transparently and seriously discussed among Member States. We therefore urge Member 
States to reject the introduction of such requirements in the updated candidate scheme, and to 
request a more thorough impact assessment of these proposals including all relevant 
stakeholders. 


1 DIGITALEUROPE, Data transfers in the data strategy: Understanding myth and reality (June 2022), available at 
httos://www.digitaleurope.org/resources/data-transfers-in-the-data-strategy-understanding-myth-and-realit 


? See Peter Swire and DeBrae Kennedy-Mayo, ‘The effects of data localisation on cybersecurity, Georgia Tech 
Scheller College of Business Research Paper No. 4030905, available at https://ssrn.com/abstract=4030905 
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dea: 


Signed: 
e DIGITALEUROPE e ITL (Estonia) 
e AAVIT (Czech Republic) e IVSZ (Hungary) 
e Abelia (Norway) e NLDigital (The Netherlands) 
e Adigital (Spain) e PIIT (Poland) 
e AFNUM (France) e Techlreland (Ireland) 
e Agoria (Belgium) e TechSverige (Sweden) 
e Bitkom (Germany) e TechUK (UK) 
e Infobalt (Lithuania) e TIF (Finland) 
e ITAS (Slovakia) e ZVEI (Germany) 


e |T Branchen (Denmark) 


